McDonald’s India operation asked users to update their McDelivery app as a 'precautionary measure' after a security firm said it had found that it was leaking personal data of over 2.2 million users.

The Indian operation of the food chain, which is owned and managed by franchisees, said in posts on Facebook and Twitter over the weekend that its website and app do not store any sensitive financial data of users.

The operation did not admit or deny that there had been a breach, but urged users to update the online ordering app as a precautionary measure. “The website and app has always been safe to use, and we update security measure on regular basis,” according to the post.

It said it had contacted McDelivery with the issue on Feb 7 and received an acknowledgement from a senior IT manager on Feb 13, but there hadn’t been information about a fix from the company even after 33 days.

Fallible said “an unprotected publicly accessible API endpoint for getting user details coupled with serially enumerable integers as customer IDs can be used to obtain access to all users personal information.”

In an update, Fallible said McDonald's India had replied to the firm that they have fixed the issue and would be releasing an official statement asking users to upgrade the app, but in another update the security firm claimed that the fix was incomplete and the endpoint is still leaking data.